CVE-2026-66764

Summary

Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application

Affected Software

VendorProductVersion RangeStatus
SAP_SESAP S/4 HANA (Reprocess Bank Statement Items)S4CORE 104affected
SAP_SESAP S/4 HANA (Reprocess Bank Statement Items)105affected
SAP_SESAP S/4 HANA (Reprocess Bank Statement Items)106affected
SAP_SESAP S/4 HANA (Reprocess Bank Statement Items)107affected
SAP_SESAP S/4 HANA (Reprocess Bank Statement Items)108affected
SAP_SESAP S/4 HANA (Reprocess Bank Statement Items)109affected

Weaknesses

  • CWE-639: CWE-639: Authorization Bypass Through User-Controlled Key

References